Req #74452 [Opn->Fbk]: Add 'Form' to Supported AuthType Authentication Methods w/ HTTP authentication
Edit report at https://bugs.php.net/bug.php?id=74452&edit=1
ID: 74452
Updated by: danack@php.net
Reported by: greywood at keystreams dot net
Summary: Add 'Form' to Supported AuthType Authentication
Methods w/ HTTP authentication
-Status: Open
+Status: Feedback
Type: Feature/Change Request
Package: Apache2 related
Operating System: N/A
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
Are you asking about https://httpd.apache.org/docs/2.4/mod/mod_auth_form.html
Because if so, are you sure the password is meant to be passed to the underlying application? The
manual implies pretty strongly that it wouldn't be except under unusual circumstances.
"Warning
A risk exists that under certain circumstances, the login form configured using inline login may be
submitted more than once, revealing login credentials to the application running underneath. The
administrator must ensure that the underlying application is properly secured to prevent abuse. If
in doubt, use the standalone login configuration."
Previous Comments:
------------------------------------------------------------------------
[2017-04-16 05:28:00] greywood at keystreams dot net
Description:
------------
Currently, the AuthType methods supported by HTTP authentication with PHP
(https://secure.php.net/manual/en/features.http-auth.php) are 'Basic' and
'Digest'.
Using the 'Form' AuthType supplied by Apache does not provide the PHP_AUTH_PW predefined
variable as desired. Only PHP_AUTH_USER and REMOTE_USER are present.
Can PHP be made to support the 'Form' AuthType and provide the PHP_AUTH_PW predefined
variable for it?
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74452&edit=1
Thread (3 messages)